Created on
09-09-2025
12:09 AM
Edited on
09-09-2025
12:09 AM
By
Jean-Philippe_P
Description | This article describes the procedure to register the FortiToken license following an RMA of a FortiGate in an HA cluster. |
Scope | FortiGate in HA, FortiToken. |
Solution |
This article focuses on an HA environment, where the FortiToken license is registered on the primary unit, and the primary unit is later RMA'ed.
In the case of setting up a High Availability (HA) cluster with multiple FortiGate units, it is required to register and apply any FortiToken Mobile licenses to the primary unit.
After HA is configured, all tokens are replicated across cluster members. Because of this, only one FortiToken Mobile license is needed per HA cluster.
In a scenario where the primary needs to be RMA'ed, the secondary unit uses the FortiToken licenses assigned to the serial number of the primary unit. When a replacement primary unit is joined to the cluster, it will be considered as a slave, as the secondary unit at that moment has the role of master.
The secondary unit (current Master) will proceed and copy the FortiToken license to the new primary unit, but those FortiTokens will still be registered to the defective primary unit’s serial number.
The assigned token will not be affected; hence, there is no need for the administrator to reprovision the assigned FortiToken, and the users do not need to reactivate the FortiToken. However, there might be an issue in assigning a new token, as the FortiToken license is registered on the new unit. Therefore, after the RMA of the primary unit, the following step can be done to re-register the FortiToken license.
|
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.